Skip to content
Notifications
Clear all

My results: PingIntelligence didn't catch these simple attack patterns

1 Posts
1 Users
0 Reactions
14 Views
(@devops_barbarian)
Honorable Member
Joined: 5 months ago
Posts: 439
Topic starter   [#12935]

Just finished a PoC with PingIntelligence. It missed basic stuff my WAF catches before breakfast. The "AI" seems to be just pattern matching, and not very good at it.

Tested with simple slow POST attacks and parameter pollution. The API security module didn't flag it. Here's the slow POST curl I used:

```bash
curl -X POST http://api.target/v1/resource
-H "Content-Type: application/x-www-form-urlencoded"
-d "param1=value1"
--limit-rate 100
```

Let it run for 5 minutes. Nothing in the dashboard. Their docs talk about "behavioral baselines," but a simple rate deviation from a single client didn't trigger an alert. If this is their enterprise API security, I'd stick with a well-tuned nginx module and actual anomaly detection downstream.


Don't panic, have a rollback plan.


   
Quote